SCA: security update for org.apache.streampark:streampark (GHSA-5v69-92vw-fmjh)

medium Tenable Self-Hosted Container Security Plugin ID 421361

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- In streampark, the project module integrates Maven's compilation capabilities. The input parameter
validation is not strict, allowing attackers to insert commands for remote command execution, The
prerequisite for a successful attack is that the user needs to log in to the streampark system and have
system-level permissions. Generally, only users of that system have the authorization to log in, and users
would not manually input a dangerous operation command. Therefore, the risk level of this vulnerability is
very low. Mitigation: all users should upgrade to 2.1.4 Background info: Log in to Streampark using the
default username (e.g. test1, test2, test3) and the default password (streampark). Navigate to the Project
module, then add a new project. Enter the git repository address of the project and input `touch
/tmp/success_2.1.2` as the "Build Argument". Note that there is no verification and interception of the
special character "`". As a result, you will find that this injection command will be successfully
executed after executing the build. In the latest version, the special symbol ` is intercepted.
(CVE-2024-29737)

See Also

https://github.com/advisories/GHSA-5v69-92vw-fmjh

Plugin Details

Severity: Medium

ID: 421361

Version: Revision 1.6

Type: Local

Family: SCA Checks

Published: 3/28/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 2.8

Percentile: 22.22

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: Medium

Base Score: 5.8

Temporal Score: 4.3

Vector: CVSS2#AV:N/AC:L/Au:M/C:P/I:P/A:P

CVSS Score Source: CVE-2024-29737

CVSS v3

Risk Factor: Medium

Base Score: 4.7

Temporal Score: 4.1

Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 7/17/2024

Vulnerability Publication Date: 7/17/2024

Reference Information

CVE: CVE-2024-29737

cwe: CWE-77